Indigo Rose Software
Indigo Rose Software
Log in to the Customer Portal Customer Login
Software Development Discussion Forums Forums
+ Reply to Thread
Results 1 to 14 of 14
  1. #1
    Join Date
    Apr 2005
    Location
    São Paulo, Brazil
    Posts
    1,259

    Password Changer for AMS

    Hello,

    I have released a new tool today. Licensed users of AutoPlay Media Studio may use this program to set a personalized password in the software that will be used to protect the *.cdd file created upon export of the project.

    By setting a new password in the editor and runtime binaries, works distributed to third parties become more resistant (but not immune, of course) to reverse engineering. With one single execution of this tool, every licensed user is able to create a new and unique autorun.exe file. Evaluation and modified programs will not be recognized by the tool.

    The use of this tool is not endorsed by Indigo Rose Software in any way, and you should use it on your own risk. Your original files are backed up, and should you need to get the original versions back (like before you perform a software update, for example) just rename them back, but please don't complain if something does not work as expected. Although the operation should be reasonably safe, I cannot guarantee that there won't be any side effects.

    You may download the tool here: Password Changer. In the zip you will find documentation in PDF format - please read it before you do anything else!

    Ulrich

  2. #2
    Join Date
    Oct 2007
    Location
    London, UK
    Posts
    1,283
    Can't wait until it does the memory as well.

  3. #3
    Join Date
    Mar 2007
    Location
    HeaveN
    Posts
    534
    Just what I needed,,, spot on upeters
    Thanks

  4. #4
    Join Date
    Mar 2009
    Posts
    17
    it says under the win32rt.dat file no original commercial binaries found? any help
    Last edited by ezasabc; 03-18-2009 at 05:11 PM.

  5. #5
    Join Date
    Apr 2005
    Location
    São Paulo, Brazil
    Posts
    1,259
    I have not included support for all versions yet. What is the full version number, shown as detected in the dialog?

    Ulrich

  6. #6
    Join Date
    Mar 2009
    Posts
    17
    the 7.5.1000.0

  7. #7
    Join Date
    Apr 2005
    Location
    São Paulo, Brazil
    Posts
    1,259
    I have now updated the tool to recognize this version, please download and try again. But you should, if possible, update your installation to the most recent version as this release has some known problems.

    Ulrich

  8. #8
    Join Date
    Jan 2001
    Location
    Anderson Island, WA, USA
    Posts
    2,609
    this tool changes 29 bytes in both the ams70.exe win32r.dat file (from the 'stock' 29 bytes to the new 29 bytes in both files)

    Anyone that could crack the original password, would be able to id the change, and use that to crack the new password...

    Not saying this isn't a step in a good direction; but it's definately not "fool proof".

    This is like locking a screen door... Keeps the honest people more honest...


    (Click here to contact me)
    Providing Independent Professional Consulting Services for IndigoRose products, World Wide.
    Located in -8:00 (-7:00 DST) GMT Timezone (Western United States)
    Do you wave? Find me at josh.assing @ googlewave.com

  9. #9
    Join Date
    Apr 2005
    Location
    São Paulo, Brazil
    Posts
    1,259
    Quote Originally Posted by jassing View Post
    Anyone that could crack the original password, would be able to id the change, and use that to crack the new password...
    You have not read the explanations in the enclosed documentation, or failed to understand what I wrote. If you process the runtime with yP.exe, it becomes much more difficult to access the password after it was changed.

    Ulrich

  10. #10
    Join Date
    Jan 2001
    Location
    Anderson Island, WA, USA
    Posts
    2,609
    Quote Originally Posted by upeters View Post
    You have not read the explanations in the enclosed documentation, or failed to understand what I wrote. If you process the runtime with yP.exe, it becomes much more difficult to access the password after it was changed.
    Sorry ulrich, I didn't think I needed to spell it all out....

    Posting "I have encrypted my file with AES 16bit encyrption, using alphanumeric characters" -- that DRASTICALLY reduces the time to crack it.

    Pushing Yoda's protector (btw: it's an old version) also drastically reduces the time to get it to an "unpacked" state. There are at least 2 unpackers out there that work on yoda's. So "here use yoda's" also says to hackers "Oh, it's protected with Yoda's... I have the unpacker for that right here...."

    As I said; it's a good step in a good direction.... It keeps honest people more honest....
    Any binary can be decompiled if someone wants the code...

    Of course, these comments are null-n-void if you've taken yoda's source & altered it such that the unpackers are thwarted.

    I think what you've done is good.... It's just not "the answer" to security/encryption.... IOW: Good Job Ulrich!

    btw: as I (also) said; I think if you're developing applications using AMS that require your code to be "protected" I think ams is probably the wrong tool...


    (Click here to contact me)
    Providing Independent Professional Consulting Services for IndigoRose products, World Wide.
    Located in -8:00 (-7:00 DST) GMT Timezone (Western United States)
    Do you wave? Find me at josh.assing @ googlewave.com

  11. #11
    Join Date
    Aug 2008
    Posts
    24
    I'm found CDD Protection flash video tutorial on one russian forum (with tools for protect):

    (URL removed, virus "Trojan horse PSW.Agent.FNL" reported in one of the tools of the package)

    Upeters - maybe some tricks you use in next releases of Password Changer?
    Last edited by Ulrich; 05-14-2009 at 10:37 AM.

  12. #12
    Join Date
    Apr 2005
    Location
    São Paulo, Brazil
    Posts
    1,259
    Quote Originally Posted by slota View Post
    Upeters - maybe some tricks you use in next releases of Password Changer?
    I doubt it. This goes way too far. As it was already said, there is no way to avoid completely to break a software protection. My intention was to hinder the decompression of the resource files, changing the default password in a secure and accessible way. This objective was reached, and while not a perfect solution, this is where I stop.

    By the way, the yP.exe shipped in this "tutorial" is the one that I compiled and shipped with my tool. I must have done something right.

    Ulrich

  13. #13
    Join Date
    Jan 2009
    Posts
    146
    Quote Originally Posted by slota View Post
    I'm found CDD Protection flash video tutorial on one russian forum (with tools for protect):

    (URL removed, virus "Trojan horse PSW.Agent.FNL" reported in one of the tools of the package)

    Upeters - maybe some tricks you use in next releases of Password Changer?
    This is Hupigon trojan (By ESET)...

  14. #14
    Join Date
    Aug 2008
    Posts
    24
    (URL removed, virus "Trojan horse PSW.Agent.FNL" reported in one of the tools of the package)
    This is Hupigon trojan (By ESET)...
    This is not virus! Some packer signatures coincide with virus signatures. Sorry.

Similar Threads

  1. Need Help: Input password without popup
    By nals in forum AutoPlay Media Studio 6.0
    Replies: 21
    Last Post: 05-04-2007, 12:08 PM
  2. Adding Password Protection
    By Desmond in forum AutoPlay Media Studio 5.0 Examples
    Replies: 0
    Last Post: 10-03-2003, 03:25 PM
  3. Reoccurring password
    By Bruce in forum AutoPlay Media Studio 4.0
    Replies: 6
    Last Post: 06-04-2003, 04:09 PM
  4. Password
    By Bruce in forum AutoPlay Media Studio 4.0
    Replies: 2
    Last Post: 05-31-2003, 05:52 PM
  5. HOWTO: Add Password Protection to Your Application
    By Support in forum AutoPlay Media Studio 4.0 Examples
    Replies: 0
    Last Post: 10-03-2002, 03:39 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Indigo Rose Software